Damian

4.8K posts

Damian banner
Damian

Damian

@notatallshaw

Geek: He/Him OSS: Nab Author, Pip/Packaging/Resolvelib maintainer Security: PSRT member

Queens, NY Katılım Mayıs 2008
410 Takip Edilen134 Takipçiler
A
A@ant_toe_knee_oh·
Just got my wristband. Still on C #hallh
English
1
0
4
442
Damian
Damian@notatallshaw·
@SDCCGuide In the same panel, it's adorable
English
0
0
0
32
Comic Con Guide
Comic Con Guide@SDCCGuide·
And the most adorable panelist award goes to Utkarsh Ambudkar's daughter on the Ghosts panel. #SDCC #comiccon
Comic Con Guide tweet media
English
3
0
16
2.5K
Charlie Marsh
Charlie Marsh@charliermarsh·
@ibuildthecloud @AnthropicAI I suspect the bottlenecks to a lot of this kind of work have shifted considerably. I’m confident that a frontier model can speed up the toolchain, but how would those changes ever get merged? Who will understand them? Who will maintain them? (I only have questions not answers.)
English
9
1
64
4.4K
Darren Shepherd
Darren Shepherd@ibuildthecloud·
If @AnthropicAI wants to really flex hard, use Fable to speed up rust tool chain. I'm not kidding. This is a task AI would be perfect at, and we would all benefit because it's clear that rust plus AI is a winning combo and holy crap, we are CPU bound.
English
5
4
42
5.8K
Damian
Damian@notatallshaw·
FYI the left most screen of #HallH has been briefly glitching every now and then. So far it comes back in less than a minute, but maybe find a seat appropriatly. #SDCC cc: @SD_Comic_Con
Damian tweet media
English
0
0
2
304
Damian
Damian@notatallshaw·
@SDCCLineUpdates A lot of people left HallH after the Wolverrine panel, don't know what the queue looks like outside
English
1
0
4
366
Damian
Damian@notatallshaw·
@simonw @baburaocandance Decades of security evidence has shown that security by obscurity is not effective, and you should never just trust the words of a company that "it's secure". Without a transparent post mortem it's impossible to assess if this is a gimmick or not.
English
0
0
5
215
Simon Willison
Simon Willison@simonw·
Tucked away in this article is an appeal to the AI skeptics to PLEASE stop writing off stories like this OpenAI accidental exploit of Hugging Face as a dishonest marketing trick Frontier models can find and exploit vulnerabilities now, it helps nobody to pretend that they can't!
Simon Willison tweet media
Simon Willison@simonw

I wrote about the completely wild incident where OpenAI were testing a new model and it broke out of its sandbox and broke INTO Hugging Face to steal the answers to the benchmark simonwillison.net/2026/Jul/22/op…

English
95
100
1.2K
108.7K
Damian
Damian@notatallshaw·
@charliermarsh If I could be paid to optimize tooling I would be doing the same, I do it for free anyway 🙃
English
0
0
6
1.1K
Charlie Marsh
Charlie Marsh@charliermarsh·
Optimizing Codex over the weekend. This is my favorite kind of work. I could do it forever.
Charlie Marsh tweet media
English
76
5
870
97.8K
Damian
Damian@notatallshaw·
@charliermarsh I find myself also doing this kind of thing, but it does require someone to know it's a good idea and that the output is sane.
English
0
0
0
167
Charlie Marsh
Charlie Marsh@charliermarsh·
Migrated our marketing site off WordPress headless CMS (please don't ask) to fully static. The kind of thing that I wouldn't have bothered with in the past. Now it takes ~zero of my time, one-shot by the model. An incredible moment in time that will only accelerate.
English
8
2
178
13.9K
Damian
Damian@notatallshaw·
@claudeai @charliermarsh FWIW, that workflow is still going while I've been out and about, 13 hours and counting:
Damian tweet media
English
0
0
0
7
Damian
Damian@notatallshaw·
@claudeai Why does OpenAI's codex not have deterministic workflows? I saw a talk (youtube.com/watch?v=KHWWSW…) on such a feature at the Rust NYC meetup in OpenAI's offices a whole month prior to Anthropic's announcement. It's the main reason I'm holding off on codex. cc: @charliermarsh
YouTube video
YouTube
English
1
0
0
59
Damian
Damian@notatallshaw·
To best make use of my time for OSS, I kick off long deterministic workflows with @claudeai code, while I'm $DAYJOBing or sleeping. I have three main use cases: * Bug sweeping * Deep dive research * Prototyping a feature by trying out all possible implementations
Damian tweet media
English
1
0
0
38
Damian
Damian@notatallshaw·
@charliermarsh Very happy to see uv pushing forward in this space, will definitely be following along, and perhaps adopting in other Python packaging tools.
English
0
0
1
370
Charlie Marsh
Charlie Marsh@charliermarsh·
PSA: Set `UV_MALWARE_CHECK=1` to cross-reference the Open Source Vulnerabilities (OSV) database prior to installing packages from a remote registry. uv will then block installation of any packages reported as malware.
Charlie Marsh tweet media
English
27
64
839
89.2K
Charlie Marsh
Charlie Marsh@charliermarsh·
Air quality in NY is bad so I have to stay inside and be on computer
English
8
0
110
9.7K
Playtonic Games & Friends - WISHLIST SUPER YL KART
Darn trees! They just love being the centre of attention! 🌳 Think you can crack the last two bits of this code? Drop a guess in the comments and you could be the lucky one to get a Steam key for early access to the Time Trial alpha playtest for Super Yooka-Laylee Kart!
English
20
11
65
7.7K
Damian
Damian@notatallshaw·
@charliermarsh Now VersionRange has landed into packaging main, allowing version algebra, I plan to start looking at uv and poetry and stealing the best idea to allow for marker algebra.
English
0
0
2
63
Charlie Marsh
Charlie Marsh@charliermarsh·
All of this is powered by a really cool library we use for marker algebra. We can perform ANDs, ORs, negations, complements, etc. on markers using binary decision diagrams.
English
1
0
14
1.7K
Charlie Marsh
Charlie Marsh@charliermarsh·
We found a few optimizations that let us reduce the size of uv.lock files by "compressing" the environment markers. Some of our lockfiles are 40-50% smaller now.
Charlie Marsh tweet media
English
9
7
351
22.2K
Sam Woj
Sam Woj@siw101·
@SD_Comic_Con All I saw is room 9 for children. Everything else is like sails pavilion
English
2
0
2
386
Damian
Damian@notatallshaw·
When optimizing your code autonomously with LLMs against a benchmark you really need to appreciate it's likely finding a local minimum. Just before your performance improved 10% after millions of tokens doesn't mean it can't improve 90% after one good idea.
English
1
0
1
166